Hi Heather and everybody,
few things I want to share here
Il giorno mar 15 set 2020 alle ore 15:52 Heather Flanagan <
hlflanagan at sphericalcowgroup.com> ha scritto:
2 - Potential new project for idpy - status?
a.
https://github.com/knaperek/djangosaml2 - Giuseppe has sent an
email to the list; Roland has indicated support. Heather will take this to
the Board.
This is linked to pySAML2. Having a project that directly uses pySAML2
that allow people to quickly set up an IdP is a good way to help direct
usability improvements for pySAML2.
djangosaml2 is a SAML2 SP implementation.
For a SAML2 IdP - based on pysaml2 (and django) - I would look at
djangosaml2idp or uniAuth. The first is a django application that still
needs programming skills to be implemented, it still have some weakness for
metadata management and someother. I was a contributor of djangosaml2idp
until I decided to fork it and create a brand new platform, called uniAuth.
This is a ready-to-go SAML2 IdP, it's not a framework application but a
standalone, monolitic, server.
https://uniauth.readthedocs.io/en/latest/
Don't worry about branding and italian localization, uniAuth have been
localized in english as well and I rely on django localization system (gnu
gettext).
The brand, template, logo and UI stuffs can be overloaded adding an app
with templates that have the same names as those contained in /idp or
/uniauth.
It has support for samesite and for who interested I sugged to look at
"refactor" branch.
3 - GitHub review
a. OIDC -
https://github.com/IdentityPython (JWTConnect-Python-OidcRP,
JWTConnect-Python-CryptoJWT, etc)
Roland is preparing an issue around session management with the
oidcendpoint. He is writing docs on how it should work, and then will work
on the code.
Ivan is working on CryptoJWK and will add a new CLI for the ‘use’ flag.
Regarding oidcendpoint I shared this notes in the past to to exemplify the
basic operation of the product, would have as audience the newcomers and
nothing else. Starting from this structure, we can then go in depth with
appropriate insights for each endpoint. It's just a tool that I created to
have a mind map, reorganize concepts and avoid running tests to study the
specific implementation of jwtconnect products
b. Satosa -
https://github.com/IdentityPython/SATOSA
Memory leak is still a mystery. This may actually be a problem with
gunicorn.
For those want to have a try with uwsgi I share here an old note I made,
with a quite usable configuration of SATOSA with uwsgi:
https://github.com/peppelinux/Satosa-saml2saml/blob/master/example/uwsgi_se…
That's some related commands:
https://github.com/peppelinux/Satosa-saml2saml/blob/8c4b84aa8713ec248e8f223…
Thanks! Heather
_______________________________________________
ciaoooo!
--
------------------------------------------------------------------------------------------------------------------
Il banner è generato automaticamente dal servizio di posta elettronica
dell'Università della Calabria
<https://www.unical.it/portale/portaltemplates/view/view.cfm?100061>